2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-40927HIGH7.2Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_designa...
CVE-2022-40926HIGH7.2Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_leave_t...
CVE-2022-40925HIGH7.2Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" fi...
CVE-2022-40924HIGH7.2Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" f...
CVE-2022-40404HIGH8.8Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/select.php.
CVE-2022-40403HIGH7.2Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit...
CVE-2022-40402HIGH8.8Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_...
CVE-2022-3295HIGH7.5Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.
CVE-2022-3119HIGH7.5The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its set...
CVE-2022-3076HIGH7.2The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary file...
CVE-2022-2987HIGH7.5The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF ...
CVE-2022-2903HIGH7.2The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could le...
CVE-2022-2352HIGH7.2The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, wh...
CVE-2022-36159HIGH8.8Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the compo...
CVE-2022-36158HIGH8Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which a...
CVE-2022-41347HIGH7.8An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the z...
CVE-2022-41343HIGH7.5registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure doe...
CVE-2022-3297HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0579.
CVE-2022-3296HIGH7.8Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
CVE-2022-41340HIGH7.5The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signa...
CVE-2022-23464HIGH7.5Nepxion Discovery is a solution for Spring Cloud. Discovery is vulnerable to a potential Server-Side Request Forgery (SS...
CVE-2022-32814HIGH7.8A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15...
CVE-2022-22629HIGH8.8A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari ...
CVE-2022-40107HIGH7.5Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formexeCommand function. This vulnerability ...
CVE-2022-40106HIGH7.5Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the set_local_time function. This vulnerability ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now